Portrait of Ahmed A., founder of Cybeus, wearing a site helmet
Founder

Ahmed A.

Senior OT Cybersecurity & Detection Engineer | OT / ICS Security | IEC 62443 · NIST SP 800-82 | Splunk · Nozomi · Darktrace OT | Energy · Oil & Gas · Critical Infrastructure

Ten years in critical infrastructure, industrial SOC operations and threat detection. Co-built Engie's global OT SOC (105 industrial sites) and now operates it as a level 3 analyst. In parallel, building an OT SOC from scratch on Darktrace/OT and a Detection-as-Code infrastructure (0 to 12 custom detection scenarios, 8 threat vectors covered). IEC 62443 and NIST SP 800-82 technical authority.

105 sitesEngie global OT SOC, co-built and operated as level 3 analyst
60% → 15%false positive rate on that OT SOC
12Darktrace/OT detection scenarios built from scratch
109industrial systems secured under the Paris 2024 Olympic mandate
31OT incident response playbooks authored
Track record

From industrial audit to detection engineering

A single client is named, with its agreement. Others are described by sector, in line with confidentiality commitments.

  1. 2025 to present

    OT detection engineer, SOC level 3 analyst

    Engie, global OT SOC co-built and now operated, 105 industrial sites

    • 26 OT detection rules in Splunk and Nozomi Vantage, covering TRITON and Industroyer
    • False positive rate cut from 60% to 15%
    • Level 3 forensic investigations on OT incidents with XSOAR, CrowdStrike and Velociraptor
    • 10 level 3 analysts trained on OT methodology, all now Nozomi NNSA certified
    • Process-aware detection rules using sensor, actuator and valve-state context
  2. 2023 to 2025

    OT/ICS cybersecurity architect, Paris 2024 Olympic Games

    Major airport operator, sole OT architect under a national security mandate

    • 109 industrial systems inventoried across 3 platforms with Nozomi, Forescout, Allentis and Darktrace OT
    • Full ICS landscape secured: SCADA, DCS, CCTV, HVAC, airfield lighting, baggage handling, explosive detection
    • 6 alerts and 2 confirmed OT incidents handled as senior architect on site
    • A 220 k€ engagement that generated a 1 M€ OT security programme
    • IoT cyber-resilience strategy, technical demonstrators, IT/OT integration services: bastion, log aggregation, OT protection platform
  3. 2022 to 2023

    IT and OT cybersecurity consultant

    Utility operator (water, energy), 15 industrial sites in Western Europe, the United Kingdom and Australia

    • Cyber resilience and security posture improved across 15 sites in 4 countries
    • PLC backup automation (SOFREL) and PLC hardening proof of concept
    • BCP/DRP procedures and offline backup policies for critical ICS environments
    • Active Directory remediation, firewall review (FortiGate, MikroTik), Windows and Linux hardening, 3-tier IT/OT architecture
  4. 2019 to 2022

    IT/OT cybersecurity auditor and consultant

    PwC France, major accounts in energy, cosmetics and aeronautics

    • 8 IT penetration tests and 2 OT/SCADA penetration tests for major French groups
    • IEC 62443 and NIST SP 800-82 audits over 3 years
    • 31 OT incident response playbooks for an oil and gas major, ransomware playbook for a major insurer
    • Industrial site audits in France and India under a global OT mandate, CSIRT member
  5. 2016 to 2019

    Cyber innovation and industrial robotics

    Airbus CyberSecurity, Valeo, Stellantis (work-study programmes)

    • European research and innovation projects in cybersecurity for Industry 4.0
    • Production line robotisation with Universal Robots (Python) and Kuka iiwa (Java) cobots
Certifications

Certifications and continuing education

Nozomi Networks Certified Analyst (NNSA)Industrial OT security and threat detection
IEC 62443Applied in audits and projects in oil and gas and energy. TÜV / Exida certification in progress
CyberX OT & IoT SecurityIndustrial asset management and threat detection
Microsoft Azure Fundamentals (AZ-900)Cloud and hybrid security
Expertise

Key skills

OT detection and SOC

  • Detection engineering
  • Detection-as-Code
  • OT threat profiling
  • Threat hunting
  • SOC level 3 operations
  • DFIR
  • Forensic investigation
  • Root cause analysis
  • Incident response

Monitoring tools

  • Darktrace/OT
  • Splunk
  • Nozomi Guardian / Vantage
  • Cortex XSOAR
  • Chronicle SOAR
  • Microsoft Sentinel
  • CrowdStrike
  • Zscaler
  • Proofpoint

Industrial systems

  • SCADA
  • DCS
  • PLC
  • HMI
  • Safety instrumented systems
  • Modbus
  • DNP3
  • OPC UA
  • Engineering workstations

Frameworks

  • IEC 62443
  • NIST SP 800-82
  • Purdue model
  • Cyber risk assessment
  • Vulnerability assessment
  • OT asset inventory

Offensive security

  • OT/SCADA penetration testing
  • IT penetration testing
  • Metasploit
  • Burp Suite
  • OWASP Top 10
  • Active Directory review

Infrastructure and languages

  • VMware vSphere
  • Veeam
  • Linux
  • Windows Server
  • Azure
  • AWS
  • Arabic (native)
  • French (native)
  • English (fluent)